AI compliance is regulatory whack-a-mole — every framework expects different controls. This matrix maps AI governance requirements to specific regulations so you know exactly what applies to your situation instead of guessing across five different compliance teams.

What's inside

Side-by-side matrix covering HIPAA, SOC 2, GDPR, PCI DSS, and state-level requirements (CCPA, etc.). Each row identifies the control, applicable regs, and risk if missing. Use it as a control coverage map and a gap analysis tool.

How to use it

  1. Fill every cell. Empty cells are usually where the actual decision is hiding.
  2. Cross-check by reading the rows and columns. Patterns in one dimension often surface insights the other missed.
  3. Date and version it. Matrices age fast — last quarter's matrix is rarely this quarter's reality.